---
title: "Attacks on TCK, Energy Sector, and iPhones: CERT-UA Reveals New Russian Cyber Threats"
description: "CERT-UA recorded over 3,000 cyber incidents in 2026. Russians are utilizing AI to attack government agencies, energy facilities, and compromise mobile devices."
date: 2026-10-01T12:20:00.000Z
lang: en
url: https://xab.info/en/posts/attacks-tck-energy-iphone-cert-ua-2026
tags: [cyber-warfare, cert-ua, russia-ukraine-war, ai-security, cyber-security]
publisher: "XAB.info"
---

# Attacks on TCK, Energy Sector, and iPhones: CERT-UA Reveals New Russian Cyber Threats

![Cybersecurity and data protection in Ukraine](https://xab.info/media/2026/10/01/ataki-tck-energetiku-iphone-cert-ua-2026/ataki-tck-energetiku-iphone-cert-ua-2026-1.webp)

## 🎯 Key Points

- Over 3000 incidents in H1 2026.
- AI used for phishing automation.
- DarkSword targets iOS, Sandworm targets energy.

During the first half of 2026, CERT-UA specialists recorded an unprecedented surge in cybercrime targeting Ukrainian infrastructure. According to a report released by the State Service of Special Communications on October 1, 2026, the number of incidents exceeded 3,000. The primary trend of the current year is the use of neural networks to automate attacks, which has allowed Russian hackers to significantly scale the intensity of phishing campaigns and the speed of malware development.

### The Aggressor's Technological Toolkit

The use of AI models has become a key lever for cybercriminals, enabling them to generate unique phishing pages tailored to specific regions and social groups. Of particular concern is the active use of legitimate platforms to mask attacks: hackers utilize GitHub, Cloudflare services, and ngrok for clandestine data exfiltration and malware distribution. ### Targets and Destructive Operations

Government bodies (37%) and state institutions (22%) remain the primary focus of the adversary. The UAC-0173 group has focused on attacks against TCK (recruitment centers), notaries, and administrative service centers, attempting to tamper with state registry data. Meanwhile, the infamous Sandworm group (UAC-0165) continues its destructive efforts to breach critical infrastructure, including energy and gas transport systems. ### Threats to Individuals and the Military

The mobile attack vector has undergone significant changes. Android malware is disguised as essential services, ranging from air raid alert maps to testing systems for military personnel. Experts identify DarkSword as a particularly dangerous tool, which allows the exploitation of vulnerabilities in the iOS operating system via compromised news resources, threatening the privacy of officials and military command.

### Contradictory Data

There is a divergence in assessments between official CERT-UA reports and independent experts. While government agencies emphasize the systematic nature of Sandworm-level attacks, third-party researchers point out that low-level AI bots can generate chaotic vulnerabilities that do not always align with the centralized strategy of Russian intelligence services, complicating the attribution of many incidents.

## 🔍 Fact-Check Verification

- [Атаки на ТЦК, энергетику и iPhone: CERT-UA раскрыла новые киберугрозы РФ](https://www.rbc.ua/ukr/news/ataki-ttsk-energetiku-ta-iphone-cert-ua-rozkrila-1790849059.html) - Основной источник данных по инцидентам.
- [Исследователи «спустили с поводка» ИИ-модели — те попытались добавить вредоносный код в ...](https://3dnews.ru/1146305/issledovateli-spustili-s-povodka-iimodeli-te-popitalis-dobavit-vredonosniy-kod-v-otkritoe-po) - Контекст рисков ИИ в кибербезопасности.

## ❓ FAQ

### Q: Which sectors were hit the hardest?
**A:** Local government bodies (37%) and governmental structures (22%).

### Q: What is DarkSword?
**A:** A tool used to compromise iOS devices through compromised web resources.